VYPR

RSGallery2

by Joomla

CVEs (7)

  • CVE-2007-6362Dec 15, 2007
    risk 0.03cvss epss 0.00

    SQL injection vulnerability in index.php in the RSGallery (com_rsgallery) 2.0 beta 5 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in an inline page action.

  • CVE-2006-6962Jan 29, 2007
    risk 0.03cvss epss 0.01

    PHP remote file inclusion vulnerability in rsgallery2.html.php in the RS Gallery2 component (com_rsgallery2) 1.11.2 for Joomla! allows attackers to execute arbitrary PHP code via the mosConfig_absolute_path parameter. NOTE: this issue may overlap CVE-2006-5047.

  • CVE-2012-4235Aug 10, 2012
    risk 0.00cvss epss 0.00

    The RSGallery2 (com_rsgallery2) component before 3.2.0 for Joomla! 2.5.x does not place index.html files in image directories, which allows remote attackers to list image filenames via a request for a directory URI.

  • CVE-2012-4071Aug 10, 2012
    risk 0.00cvss epss 0.00

    Cross-site scripting (XSS) vulnerability in the comments module in the RSGallery2 (com_rsgallery2) component before 2.3.0 for Joomla! 1.5.x, and before 3.2.0 for Joomla! 2.5.x, allows remote attackers to inject arbitrary web script or HTML via crafted BBCode markup in a comment.

  • CVE-2012-3554Aug 10, 2012
    risk 0.00cvss epss 0.00

    SQL injection vulnerability in the RSGallery2 (com_rsgallery2) component before 2.3.0 for Joomla! 1.5.x, and before 3.2.0 for Joomla! 2.5.x, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2006-5046Sep 27, 2006
    risk 0.00cvss epss 0.00

    Unspecified vulnerability in RS Gallery2 (com_rsgallery2) 1.11.3 and earlier for Joomla! has unspecified impact and attack vectors, related to lack of "hardened language files."

  • CVE-2006-5047Sep 27, 2006
    risk 0.00cvss epss 0.00

    Unspecified vulnerability in rsgallery2.html.php in RS Gallery2 component (com_rsgallery2) before 1.11.3 for Joomla! allows attackers to execute arbitrary code.